Encryption everywhere
TLS 1.2+ in transit. AES-256 at rest for our primary databases, object storage, and backups. Customer secrets (API keys, OAuth tokens) are stored encrypted with per-tenant data keys.
Güvenlik özeti
Convia, müşteri sohbetlerine güvenen işletmelerin sıkıcı ama kritik güvenlik sorularıyla uğraşmak zorunda kalmaması için tasarlandı. Aşağıda ne yaptığımız, üzerinde çalıştıklarımız ve güvenlik ekibinizin imzadan önce okumak isteyeceği bilgiler var.
Security pillars
TLS 1.2+ in transit. AES-256 at rest for our primary databases, object storage, and backups. Customer secrets (API keys, OAuth tokens) are stored encrypted with per-tenant data keys.
Email + password with bcrypt hashing, Google OAuth, and JWT short-lived sessions. SAML SSO for enterprise tenants. Optional 2FA on the roadmap.
Strict tenant isolation at every layer — database, cache, file storage. Server-side checks on every request validate ownership before any read or write.
Per-agent rate limits, automatic spam detection on Redis, IP-aware blocklists with safe-contact exceptions, hard guardrails against giving advice on regulated topics.
Hosted on managed cloud (EU regions available on enterprise). Daily encrypted backups with 30-day retention. Continuous vulnerability scanning on container images and dependencies.
Structured logs, error tracking, and uptime monitoring on every public surface. Incident response runbook with named on-call rotation for paid plans.
We capture only what your agent needs to do its job. Lead data is yours. You can delete a lead, a conversation, or an entire workspace from the dashboard.
Every administrative action (settings change, agent edit, team-member addition) is logged. Enterprise plans get streaming export.
We're honest about what's done and what's in progress. The current state of compliance and audits is documented on our Trust center. For procurement reviews, request a security pack via the contact form or the Enterprise page.
We take responsible disclosure seriously. If you believe you've found a security issue, please email help@conviaagent.com with a description of the issue, steps to reproduce, and any impact you've identified. We acknowledge reports within one business day and will keep you updated on the fix.
Please don't test against other customers' tenants — use your own workspace or contact us first to set up a controlled test environment.